Remember Higinio Ochoa (“w0rmer” or @Anonwormer) of Cabin Cr3w? This site had reported on some of their hacking activities back in the day. “Back in the day” meaning before Ochoa was arrested and went to prison. Alex Goldman has a story on Digg about Ochoa’s life as an offline programmer following his release from prison. You young…
Category: Commentaries and Analyses
Congress to banks: Admit you’ve been hacked!
Jose Pagliery reports: Banks have lost so much consumer information to hackers this year that two members of Congress are asking them to come clean with the extent of the damage. Tuesday morning, 16 financial institutions will receive letters from Sen. Elizabeth Warren and Rep. Elijah E. Cummings asking them to admit that they have…
The hotly disputed black magic of data breach cost estimates
Robert Hackett reports: A single stolen customer record costs probably somewhere between $0.58 and $201. What’s the best model? A few weeks ago Fortune visited a law firm where one partner lamented the quality of cost estimates for big companies suffering data breaches—a vital consideration for businesses seeking to manage their risk and score reasonably priced insurance…
Point-of-Sale vendor has used the same admin password for 25 years
Alan Martin reports: A major vendor of point-of-sale terminals has not changed the default passwords used on its devices in a quarter of a century, researchers have revealed at RSA 2015. The firm was not named during the presentation by Charles Henderson and David Byrne for security reasons, but it is said to be a widely used manufacturer. Although…
Oregon state data center security flaws found in 2012 still not fixed
Hillary Borrud reports: Three years after state auditors identified security weaknesses at Oregon’s main data center in Salem, the state has yet to fix some of the problems. The vulnerabilities were outlined in a secret March 2012 letter to Michael Jordan, who, at the time, was director of the Department of Administrative Services, which manages…
The long road to catching “Bitcoin Baron,” the “Internet’s most inept criminal”
Jack Smith IV has a piece on Randall Charles Tucker (a/k/a “Bitcoin Baron”), who was recently arrested. Smith’s piece includes a recap of some of Tucker’s attacks on sites, but also includes chat transcripts that give insight into his thinking and behavior. The Observer article will be of interest to those interested in the motivation and…